Not the first incident

Operator of Taco Bell, Pizza Hut, and Panera Bread Reports Data Breach

Taco Bell
Facebook
X
LinkedIn
Reddit
WhatsApp
Source: WD StockPhotos/Shutterstock.com

Pan American Group, one of the largest franchise operators in the US, has disclosed a data breach in which files containing employee information leaked out.

According to a filing submitted to the California Attorney General’s Office, the company discovered suspicious network activity on April 9, 2026. The subsequent investigation revealed that an unknown actor had access to certain servers between April 8 and 9, i.e., for around one day, and retrieved or obtained files stored there during that period. Which specific data categories were affected is not clearly evident from the publicly available notice; however, a forensic investigation revealed that full names, driver’s license numbers, and other ID numbers of employees were disclosed, among other things.

Ad

According to its own statements, the company has so far found no evidence of actual identity theft or fraud in connection with the incident. As a precaution, Pan American Group is nevertheless offering affected employees 12 months of free credit monitoring and identity theft protection via the TransUnion service CyberScout.

Part of a large franchise empire

Pan American Group is a subsidiary of Flynn Group, one of the largest franchise operators in the US with more than 430 Applebee’s locations, 280 Taco Bell restaurants, over 360 Arby’s locations, and 930 Pizza Hut and Panera Bread locations. Flynn Group’s portfolio also includes Wendy’s restaurants and gym locations belonging to the Planet Fitness chain.

Not the first incident involving the same brands

The same attacker group had previously claimed the publication of data from the brands Wendy’s and Burger King, specifically at European franchise locations of Wendy’s in the UK and Burger King in France; the allegedly stolen datasets were advertised on an underground marketplace. Taco Bell and Pizza Hut themselves were previously affected by data breaches: In 2023, a ransomware attack on then-parent company Yum Brands temporarily paralyzed around 300 restaurants. The US food industry overall has also repeatedly come into the crosshairs recently, for example in May of this year at baked goods manufacturer Rich Products following a successful phishing attack.

Ad

(Editorial Team)

Ad

Weitere Artikel